MCPLow riskUnclaimed

formio-mcp

Create and manage Form.io forms, resources, actions, roles, and projects from your AI agent.

form.ioform.io/formio-mcp★ 8Updated Oct 5, 2026

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "io.form/formio-mcp",
  "description": "Create and manage Form.io forms, resources, actions, roles, and projects from your AI agent.",
  "repository": {
    "url": "https://github.com/formio/ai",
    "source": "github",
    "subfolder": "packages/mcp-server"
  },
  "version": "0.14.1",
  "websiteUrl": "https://form.io",
  "packages": [
    {
      "registryType": "npm",
      "identifier": "@formio/mcp",
      "version": "0.14.1",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "Optional, and the WEAKEST of the three project sources: a committed formio.json found by walking up from the working directory wins, then the per-directory mapping project_set writes, then this. It pins nothing — project_set can redirect a directory whose environment names a different project. Useful for a launch with nowhere to record a project, such as CI or a container (e.g. https://examples.form.io on the hosted cloud; self-hosted it is either https://your-project.your-domain.com or https://your-host/project-name, depending on how that deployment routes projects). Leave it unset and the agent asks for a project and records it per directory.",
          "format": "string",
          "name": "FORMIO_PROJECT_URL"
        },
        {
          "description": "Optional, and usually unnecessary: the base URL is DERIVED from the project URL — https://api.form.io for a project on a form.io host, the parent path for a project addressed as a sub-directory — and is asked for only when it cannot be derived, which is a path-less project URL on a customer domain. There is no default. Like FORMIO_PROJECT_URL it is the weakest source, behind a committed formio.json and the per-directory mapping.",
          "format": "string",
          "name": "FORMIO_BASE_URL"
        },
        {
          "description": "Form.io project API key. Optional — when omitted the server uses a browser-based portal login flow to obtain a JWT.",
          "format": "string",
          "isSecret": true,
          "name": "FORMIO_API_KEY"
        },
        {
          "description": "URL of a custom login form used by the browser-based portal login flow. Defaults to the deployment's portal login form.",
          "format": "string",
          "name": "FORMIO_LOGIN_FORM"
        },
        {
          "description": "Set to 1 to attempt the browser login even where the server detects it cannot present one (CI, a container, a remote shell with no display). Use it when the login page is reachable from a browser elsewhere.",
          "format": "string",
          "name": "FORMIO_FORCE_BROWSER"
        },
        {
          "description": "Set to 1 to skip TLS certificate verification. For local development against self-signed certificates only — never enable in production.",
          "format": "string",
          "name": "FORMIO_INSECURE_TLS"
        }
      ]
    }
  ]
}

Permissions

DeclaredDetected
Runs code—node
Installs—npm:@formio/mcp@0.14.1
Runs install scripts—None
NetworkNoneNone
Needs credentialsFORMIO_API_KEYFORMIO_API_KEY
Outside the workspace—None
Agent tools—None

Checks

Low risk · Nothing worth a warning was found.

Not reviewed by a person · Checked by rules; the model review is not switched on yet.

Versions

  1. #10.14.1latestOct 7, 2026